Privacy Policy — Rispost
Effective date: Sep 16, 2026 Contact: hello@rispost.com
This policy describes what data Rispost (“the App,” “we,” “us”) collects when you create an account, connect your X (Twitter) account, and use the browser extension, and how we use it.
What we collect
- Account data — We store the name and email address associated with your Rispost account, your authentication credentials (handled by our authentication provider; passwords are stored as salted hashes, never in plain text), and basic account preferences such as your auto-reply setting. We never request or store your X password.
- X connection — When you connect X, we store the OAuth access token X
issues and your X username (used only to recognize your own posts so they
aren’t scored or targeted). Connecting X currently grants Rispost
read-only access to your public profile and identity — specifically the
users.read,users.email, andtweet.readscopes. We do not request write, posting, direct-message, or list-management permissions, and the App cannot post, reply, like, follow, or otherwise take any action on X on your behalf. When the extension drafts a reply, it types the text into X’s own reply composer for you to review, edit, and post yourself. - Targeting profile — During onboarding you choose a goal (for example, building authority or finding customers) and answer a short free-text question about your work or interests. We store your answer and use it, together with an AI-generated summary of it, to personalize the replies and takes the App generates for you.
- Topics — We store the topic names and descriptions you create and an embedding of each description, used to score how relevant an encountered post is to that topic.
- Timeline posts and embeddings — The browser extension sends the text of an encountered X post to the App, which sends it to OpenAI once to create a numerical embedding. We discard the post text immediately after embedding — it is never stored. For home-timeline posts, we retain the resulting embedding and the X post ID in a rolling personal corpus of at most 1,000 posts, used to score topic relevance. Embeddings from other views (for example, a profile or search page) are retained for up to 24 hours for retry and deduplication and never join that corpus.
- Reply generation data — When you ask the App to suggest takes or draft a reply to a tweet, we send the tweet’s text, its author’s handle, public bio, and follower count, any quoted post’s text and author information, and publicly hosted image URLs attached to the tweet or quoted post, to OpenAI to generate candidate positions (“takes”) and reply drafts. We do not upload or store the images ourselves — the image URLs are passed through to OpenAI, which fetches them directly. We also send your targeting goal and goal-context answer (see above) so replies reflect your stated goal. We store the tweet text, this contextual data, and the resulting takes and generated replies, associated with your account, so we can return cached results and avoid re-generating identical output.
- Tweet context lookups — To get richer context than the extension can scrape from the page (such as a quoted post’s author bio or an accurate follower count), we send the tweet’s ID to twitterapi.io, a third-party X data provider, and use its response in place of or alongside the scraped page content described above.
- Live research queries — When generating takes or a reply, the App may decide a short, specific factual question needs answering (for example, to verify a claim). If so, we send only that generated question — never the raw tweet text, images, or author information — to xAI’s Grok, which searches X for a current, verifiable answer. We store the question and Grok’s answer alongside the take/reply data described above.
- Usage and billing data — We record which billing-limited actions (reply generation, web-search-backed research) you take and when, to enforce plan limits; these records contain no post content. If you subscribe to a paid plan, Stripe processes your payment and stores your payment details directly — we never see or store your card number. We keep a minimal billing record (your Stripe customer and subscription IDs, plan, and status) to know what you’re entitled to.
- Operational logs — Like most services, our infrastructure and AI providers generate short-lived operational logs (timing, error, and request-metadata logs) used for debugging and abuse monitoring.
- Waitlist signups — If you join our waitlist before creating an account, we store the email address you provide and your queue position, used only to notify you when access opens and to send your discount code.
What we don’t collect
- We do not collect or store your X password.
- We do not retain raw encountered post text after its embedding is created.
- We do not download or store the images attached to tweets — only their public URLs are passed to our AI provider.
- We do not request or hold any permission to post, reply, message, follow, or otherwise act on X on your behalf.
How we use your data
- Encountered-post embeddings and topic embeddings are compared to score how relevant a post is to your topics.
- Tweet content, author/quoted-post context, image URLs, and your targeting profile are sent to OpenAI to generate reply takes and drafts.
- A narrow, generated research question (never raw tweet content) is sent to xAI (Grok) to look up current information on X when a take or reply would benefit from it.
- A tweet ID is sent to twitterapi.io to fetch public tweet/author context we can’t reliably scrape from the page.
- Per OpenAI’s and xAI’s API terms, data submitted via their APIs is not used to train their models by default.
- Stripe processes payments for paid plans under its own privacy policy and terms.
Data retention
- We retain your OAuth token for as long as your account is connected to the App. You can revoke access at any time via X’s Connected Apps settings, which immediately invalidates our stored token.
- A home-timeline embedding is retained until it is evicted from your 1,000-post rolling corpus. A non-corpus embedding expires after 24 hours.
- Reply-takes data (tweet text, context, generated takes and replies) is retained per tweet you’ve generated takes or replies for, so we can serve cached results without regenerating them, until you delete your account.
- Topic data, your targeting profile, and derived similarity contributions are retained until you delete the topic or your account.
- Deleting your account (available from account settings) permanently removes all of the above data and cancels any active subscription.
Data sharing
We do not sell your data. We share the data described above with OpenAI and xAI solely to generate takes, replies, and research answers, with twitterapi.io solely to look up public tweet context, and with Stripe solely to process payments. With your marketing consent, we also share advertising measurement events with Reddit as described below. We do not share your X password or Rispost credentials with anyone.
Your rights
You may revoke Rispost’s access to your X account at any time via X’s settings. You may delete your account and all associated data at any time from account settings, or request deletion by contacting hello@rispost.com. If you are located in the EU/EEA or UK, you have rights under GDPR including access, correction, and erasure of your personal data; if you are a California resident, you have similar rights under the CCPA. Contact us at hello@rispost.com to exercise these rights.
Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected here with an updated effective date.
Optional advertising measurement and activation
With your opt-in, our website and signed-in web app load the Reddit Pixel to measure marketing page visits, installation button clicks, confirmed fresh extension installations, new verified signups, and the first reported paid subscription checkout. Purchase events include the actual charged value and currency. Reddit receives browser and network information (including IP address, page context and cookie identifiers). We send opaque conversion identifiers; we do not include account identifiers, email, X profiles, tweets, or reply text in these events. See Reddit’s privacy policy.
Use Privacy choices on either site to accept or reject optional marketing cookies. Your choice is stored for six months and shared across our production subdomains. Rejecting prevents the Pixel from loading. Withdrawing consent stops future events, clears accessible Reddit and campaign cookies, and reloads the page. We cannot clear cookies on Reddit’s own domains or recall events already received by Reddit.
After consent, we keep first-touch landing origin/path and bounded utm_source, utm_medium, utm_campaign, and utm_content values in a session cookie. When you create an account, this acquisition metadata is saved once. A pending installation attempt remains in session storage for up to five minutes; an opaque reported installation token is retained locally to prevent repeat reports. The extension exposes only installation presence, its fresh-install time, and an opaque token to our allowlisted website origins. It does not load the Reddit Pixel.
We retain signup eligibility, reporting status, and the time of your first successfully generated and cached reply with your account until account deletion. The reply timestamp is internal product activation measurement, independent of marketing consent, and is not sent to Reddit. Acquisition metadata and reporting records are deleted with your account. Withdrawing consent stops future browser measurement but does not automatically erase these existing account records; you can request erasure using the contact above.